CVE-2024-5554: Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) <= 5.6.11 - Authenticated (Contributor+) Stored Cross-Site Scripting
The Element Pack Elementor Addons (Header Footer, Template Library, Dynamic Grid & Carousel, Remote Arrows) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘onclickevent’ parameter in all versions up to, and including, 5.6.11 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. CVE-2024-39667 is likely a duplicate of this issue.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-5554?
CVE-2024-5554 has a medium severity rating due to its potential for storing and executing cross-site scripting attacks.
How do I fix CVE-2024-5554?
To fix CVE-2024-5554, update the Element Pack Elementor Addons plugin to version 5.6.12 or higher.
What versions of the Element Pack Elementor Addons are affected by CVE-2024-5554?
All versions up to and including 5.6.11 of the Element Pack Elementor Addons are affected by CVE-2024-5554.
What type of vulnerability is CVE-2024-5554?
CVE-2024-5554 is classified as a Stored Cross-Site Scripting (XSS) vulnerability.
What input is exploited in CVE-2024-5554?
CVE-2024-5554 exploits the 'onclick_event' parameter due to insufficient input sanitization.